Ir al contenido principal

Privacy Policy

Last updated: April 06, 2026

TestPath ("we", "us", "our") is a QA learning platform operated by Agustin Gottlieb. We are committed to protecting your personal data in compliance with the EU General Data Protection Regulation (GDPR) and applicable privacy laws.

1. Data Controller

The data controller is TestPath, contactable at privacy@testpath.dev.

2. What Data We Collect

CategoryDataPurposeLawful Basis
AccountName, email, password (hashed)Authentication & identificationContract (Art 6.1.b)
LearningLesson progress, quiz answers, challenge submissionsTrack learning progress, award XPContract (Art 6.1.b)
PaymentStripe customer ID, subscription statusProcess subscription paymentsContract (Art 6.1.b)
ProfileBio, location, GitHub/LinkedIn URLs (optional)Public profile, community featuresConsent (Art 6.1.a)
CommunicationsSupport tickets, feature suggestionsCustomer supportContract (Art 6.1.b)
MarketingEmail preferences, streak remindersRetention emails (opt-in only)Consent (Art 6.1.a)
SecurityMasked IP address, login eventsFraud prevention, rate limitingLegitimate interest (Art 6.1.f)

3. How We Use Your Data

4. Data Processors (Third Parties)

ProcessorPurposeLocationSafeguards
StripePayment processingUSADPA + Standard Contractual Clauses
BrevoEmail deliveryEU (France)GDPR-compliant, EU-based processor
HetznerServer hosting + database backupsEU (Germany)GDPR-compliant EU hosting, Object Storage in EU

5. Your Rights (GDPR)

Under GDPR, you have the right to:

6. Data Retention

7. Cookies

We use only essential session cookies to keep you logged in. We do not use tracking cookies, analytics cookies, or third-party advertising cookies. No cookie consent is required for strictly necessary cookies under GDPR.

8. Children's Privacy

TestPath is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at privacy@testpath.dev.

9. International Transfers

Our infrastructure is primarily EU-based: Hetzner (Germany) for hosting and backups, Brevo (France) for email. Stripe (USA) processes payments under Standard Contractual Clauses (SCCs) as approved by the European Commission. All database backups remain in the EU.

10. Security

We protect your data with: HTTPS encryption in transit, bcrypt password hashing, HSTS headers, Content Security Policy, rate limiting, and access controls. Database backups are encrypted and stored in the EU.

11. Data Breach Notification

In the event of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Article 33.

12. Contact & Complaints

For privacy requests: privacy@testpath.dev

You have the right to lodge a complaint with your local data protection authority. For Spain: Agencia Española de Protección de Datos (AEPD).

13. Changes to This Policy

We will notify you of material changes via email. Continued use of TestPath after changes constitutes acceptance of the updated policy.